An integrated conceptual model for information system security risk management and enterprise architecture management based on TOGAF

5Citations
Citations of this article
74Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. According to our research agenda, a first step towards a better integration of both domains is to define an EAM-ISSRM conceptual integrated model. To build such a model, we will improve the ISSRM domain model, a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The contribution of this paper is focused on the improvement of the ISSRM domain model with the concepts of TOGAF, a well-known EAM standard.

Cite

CITATION STYLE

APA

Mayer, N., Aubert, J., Grandry, E., & Feltus, C. (2016). An integrated conceptual model for information system security risk management and enterprise architecture management based on TOGAF. In Lecture Notes in Business Information Processing (Vol. 267, pp. 353–361). Springer Verlag. https://doi.org/10.1007/978-3-319-48393-1_27

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free